Fortra researchers corroborated ExfilSquad’s July 26 breach claims and tied the alleged exfiltration to misconfigured Microsoft Power Pages portals that exposed Microsoft Dynamics 365 data across governments, schools, airlines, insurers, and private companies. The group says it holds records from roughly 15 organizations, including Atlanta, Allstate, the U.K. Department for Education, Frontier Airlines, and Microsoft.
The break is in the portal, not the backend app. Power Pages is a public-facing website layer; when it is wired to D365 with the wrong access settings, outsiders can read records they were never meant to see, so a healthy core system can still leak data through its front door.
For teams that publish customer or citizen records through portals, the exposure sits in that trust link between the public site and the SaaS data behind it. A compromise of the portal layer can create broad data loss without ransomware or a server exploit, and the backend may remain untouched.